unsafe_input = ActionController::Base.helpers.escape_javascript("'hi'") # comes from user input
html = "<script>console.log('((url))');</script>"
html.gsub("((url))", unsafe_input)
output: "<script>console.log('');</script>hi');</script>');</script>"
expected: <script>console.log('\'hi\'');</script>
I'm trying to build dynamic HTML to inject on the page. This html is a mix of my own (safe) html, and any unsafe code (in the example above, unsafe_input) is ran through escape_javascript and inserted ONLY between single quotes in a javascript variable.
I don't use escape_javascript in the view as building the html is quite complicated and I don't want to do it all inside the view... I do it in a model using the helper, and in the html I simply have:
<%= @combined_html.html_safe %>